CVE-2026-22678

Source
https://cve.org/CVERecord?id=CVE-2026-22678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22678
Published
2026-05-21T20:59:52.927Z
Modified
2026-07-15T02:17:33.093114092Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Webmin < 2.641 Stored XSS via System and Server Status
Details

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in savetmpl.cgi and rendered unescaped in listtmpls.cgi.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22678.json",
    "cna_assigner": "VulnCheck",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/webmin/webmin

Affected ranges

Type
GIT
Repo
https://github.com/webmin/webmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.641"
        }
    ]
}

Affected versions

1.*
1.700
1.710
1.720
1.730
1.740
1.750
1.760
1.770
1.780
1.790
1.800
1.801
1.810
1.820
1.830
1.831
1.840
1.850
1.860
1.870
1.880
1.890
1.900
1.910
1.920
1.930
1.940
1.941
1.950
1.951
1.953
1.954
1.955
1.960
1.962
1.970
1.972
1.973
1.974
1.980
1.982
1.983
1.984
1.990
1.991
1.993
1.994
1.995
1.996
1.998
1.999
2.*
2.000
2.001
2.003
2.010
2.011
2.012
2.013
2.020
2.021
2.100
2.103
2.104
2.105
2.110
2.111
2.200
2.201
2.202
2.301
2.302
2.400
2.401
2.402
2.501
2.510
2.520
2.600
2.610
2.620
2.621
2.630
2.640

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22678.json"